Privacy Policy

Effective Date: February 10, 2026
Last Updated: August 30, 2026

Your Privacy Matters

IANternet Media (“OpenAssist,” “we,” “us,” or “our”) operates OpenAssist.io, a managed deployment platform for OpenClaw AI agents. This Privacy Policy explains how we collect, use, share, and protect your personal information.

By using OpenAssist, you agree to the data practices described in this policy. If you do not agree, please do not use our Service.


1. INFORMATION WE COLLECT

1.1 Account Information

When you create an account, we collect:

  • Email address (via Google OAuth or direct registration)
  • Display name (from your Google profile or provided by you)
  • Profile picture URL (from Google, optional)
  • User ID (automatically generated by Supabase)
  • Account creation date and last login timestamp

1.2 Subscription & Payment Data

To process payments, we collect:

  • Payment information (processed and stored by Stripe—we never store full credit card numbers)
  • Billing address (required by Stripe for payment processing)
  • Subscription plan (Starter, Standard, or Pro)
  • Subscription status (active, trial, inactive, canceled)
  • Billing history (invoices, payment dates, amounts)
  • Stripe Customer ID (to link your account with Stripe records)

Important: Credit card details are handled exclusively by Stripe (PCI-DSS Level 1 certified). We do not have access to your full card numbers.

1.3 Service Usage Data

To provide the OpenAssist dashboard and manage your agents, we collect:

  • Tasks: Title, description, status, assigned agents, creation/completion timestamps
  • Agents: Name, role, personality configurations (SOUL.md, IDENTITY.md), session keys
  • Protocols: Workflow definitions, categories, steps, agent types
  • Schedules: Cron expressions, task templates, execution logs, success/failure status
  • Activity logs: Task status changes, agent actions, system events, timestamps
  • Chat messages: Conversations between you and your OpenClaw agents
  • Instance metadata: DigitalOcean droplet IDs, IP addresses, regions, plans, status (active/stopped/provisioning)
  • Configuration files: HEARTBEAT.md, AGENTS.md, memory files (stored on your droplet)

1.4 API Keys & Credentials (Encrypted)

You provide API keys that we store securely:

  • Anthropic/OpenAI API keys: Stored encrypted in your DigitalOcean droplet’s environment variables (we cannot decrypt or access them)
  • DigitalOcean API token: Encrypted in Supabase, used to manage your droplets (create, start, stop, destroy)
  • Cloudflare credentials (optional): If you use custom DNS, stored encrypted for DNS configuration

We do NOT:

  • Store API keys in plain text
  • Access your AI model API keys
  • See your AI provider billing or usage data

1.5 Technical & Analytics Data

Automatically collected:

  • IP address: For security, fraud prevention, and approximate geolocation
  • Browser information: Type, version, language, user agent
  • Device data: Type (desktop/mobile/tablet), operating system, screen resolution
  • Cookies: Authentication session, preferences (see Section 9)
  • Usage analytics: Via Google Analytics (see Section 1.6)

Location data:

  • Geolocation: Approximate location inferred from IP address (city/country level, not precise GPS)
  • Timezone: Browser timezone for scheduling features
  • Droplet region: You manually select DigitalOcean regions (NYC, SF, Toronto, Amsterdam, Singapore, etc.)

1.6 Google Analytics

We use Google Analytics to understand how users interact with OpenAssist:

What Google Analytics collects:

  • Page views and navigation paths
  • Feature usage (which tabs/buttons are clicked)
  • Session duration and bounce rates
  • Anonymized demographic data (age range, gender, interests—not linked to your identity)
  • Device and browser statistics

What Google Analytics does NOT collect:

  • Your email address or personally identifiable information (PII)
  • Chat message content or AI prompts
  • Payment information or API keys

Your choices:

Data retention: Google Analytics data is retained for 26 months, then automatically deleted.

Google’s Privacy Policy: https://policies.google.com/privacy

1.7 Email Communications (Brevo)

We use Brevo (formerly Sendinblue) to send emails:

What Brevo processes:

  • Your email address
  • Display name
  • Email engagement data (opens, clicks, bounces)
  • Subscription preferences (marketing opt-in/opt-out)

Types of emails:

  • Transactional (required): Welcome emails, billing notifications, password resets, security alerts
  • Marketing (optional): Feature announcements, tips, newsletters, promotional offers

Brevo does NOT:

  • Sell your data to third parties
  • Send emails on our behalf without your consent (for marketing)

Brevo’s Privacy Policy: https://www.brevo.com/legal/privacypolicy/

1.8 Google Account Data (Google Drive & Google Ads)

Connecting a Google account is optional. Nothing in this section applies unless you choose to connect one, and you can disconnect at any time. We request the narrowest permissions each feature needs:

  • Identity (openid, email): Your Google account’s email address, so the dashboard can show you which account is connected.
  • Drive per-file access (drive.file): Reaches only the files OpenAssist itself creates and the files you explicitly select through a picker. It does not grant access to the rest of your Drive.
  • Drive folder names (drive.metadata.readonly): Optional, and requested only if you press “Reconnect (expand scopes)” to browse your folder tree and set a default upload folder. It returns folder and file names and IDs — never file contents.
  • Google Ads (adwords): Reads and manages the Google Ads accounts you choose to link, for the Google Ads app.

What we access and store:

  • Google Drive: Listing files and folders, reading file metadata, downloading the contents of files you or your agent request, and uploading files your agent produces. File contents pass through our broker to your agent; we do not keep a copy in our database. If your agent saves a downloaded file, it is written to your own droplet’s disk, which is your storage and is destroyed with the droplet.
  • Google Ads: The list of Ads accounts your Google login can reach, so that you can choose one; and, for the account you link, campaign, keyword, search-term and performance reporting. That reporting is cached in your account’s Google Ads tables in our database so the dashboard and your agent can query it without re-fetching from Google on every request.
  • Credentials: Your Google refresh token, encrypted with AES-256-GCM before it is stored. Access tokens are minted server-side on demand and are never returned to your browser. Your droplet holds no Google credentials at all — it reaches Drive only through our broker, which authenticates the droplet and applies your account’s permissions.

How we use it: Only to operate the features you invoke — showing your Drive files in a picker, uploading what your agent generates, and producing the Google Ads reports and recommendations you ask for. Where answering your request requires an AI model, the content is processed by the AI provider configured for your instance: your own provider account when you supply the API key, or Anthropic through our gateway on credits-based plans.

We do NOT:

  • Use Google user data to develop, improve, or train any AI or machine-learning model, generalized or otherwise
  • Use Google user data for advertising, ad targeting, or building audiences
  • Sell Google user data, or transfer it to data brokers or information resellers
  • Read your Google user data as humans, except with your explicit permission (for example, when you ask us to investigate a specific problem), where necessary for security purposes such as investigating abuse, or where required by law

Revoking access and deletion:

  • Disconnecting the integration in the dashboard revokes the refresh token at Google and deletes the stored credentials from our database.
  • You can revoke OpenAssist independently at any time from your Google account’s permissions page: https://myaccount.google.com/permissions
  • Removing the Google Ads app deletes its cached reporting for your account. Deleting your OpenAssist account removes everything described here, as set out in Section 4.
  • Revoking access does not retroactively delete files already written to your own Google Drive, or files your agent already saved to your droplet.

Limited Use. OpenAssist’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.


2. HOW WE USE YOUR INFORMATION

2.1 To Provide the Service

  • Authentication: Log you in securely via Supabase and Google OAuth
  • Agent deployment: Provision DigitalOcean droplets running OpenClaw
  • Dashboard functionality: Display tasks, agents, protocols, schedules, and activity logs
  • Chat interface: Route messages between you and your AI agents
  • Data storage: Persist your data in Supabase (tasks, agents, configurations)
  • DNS configuration: Set up secure Cloudflare domains for OpenClaw gateway access
  • Billing: Process payments via Stripe and manage subscriptions

2.2 To Improve the Service

  • Analytics: Understand feature usage and user behavior via Google Analytics
  • Debugging: Identify and fix errors, crashes, and performance issues
  • Optimization: Improve page load times, reduce API latency, enhance UX
  • Feature development: Prioritize new features based on usage patterns

We do NOT:

  • Read your chat messages or AI prompts for service improvement
  • Train AI models on your data
  • Use your agent outputs for any purpose beyond displaying them to you

2.3 To Communicate With You

Transactional emails (mandatory):

  • Welcome email after signup
  • Billing notifications (payment success/failure, subscription renewal)
  • Security alerts (suspicious login attempts, password changes)
  • Service updates (planned maintenance, critical bug fixes)

Marketing emails (optional, with your consent):

  • Product updates and new features
  • Tips and tutorials for using OpenAssist
  • Promotional offers and discounts
  • Blog posts and industry insights

You can opt out of marketing emails at any time via:

Transactional emails cannot be opted out (required for account security and billing).

2.4 For Legal & Security Purposes

  • Fraud prevention: Detect and prevent unauthorized access, payment fraud, abuse
  • Terms enforcement: Investigate violations of our Terms of Service or Acceptable Use Policy
  • Legal compliance: Respond to subpoenas, court orders, law enforcement requests
  • Dispute resolution: Provide evidence in arbitration or legal proceedings
  • Security monitoring: Log failed login attempts, unusual API usage, DDoS attacks

3. HOW WE SHARE YOUR INFORMATION

3.1 Third-Party Service Providers

We share data with trusted vendors who help us operate OpenAssist:

ServiceData SharedPurposePrivacy Policy
SupabaseAll service data (tasks, agents, auth sessions, activity logs)Database & authenticationSupabase Privacy
DigitalOceanDroplet configs, your DO API token, instance metadataAgent hosting infrastructureDigitalOcean Privacy
VercelDashboard code, session data (via Supabase cookies)Dashboard hosting (static files, serverless functions)Vercel Privacy
CloudflareDomain names, DNS records, agent IP addressesSecure DNS and DDoS protectionCloudflare Privacy
StripeEmail, name, billing address, payment methodPayment processing (PCI-DSS compliant)Stripe Privacy
Google OAuthEmail, name, profile picture (optional)Authentication (single sign-on)Google Privacy
Google AnalyticsIP address (anonymized), page views, device dataUsage analytics and insightsGoogle Privacy
BrevoEmail address, name, engagement dataTransactional and marketing emailsBrevo Privacy
Anthropic/OpenAIYour prompts and AI outputs (via your API keys, not ours)AI model inference (you control this data)Anthropic Privacy / OpenAI Privacy

All vendors:

  • Are contractually obligated to protect your data
  • May only use data to provide services to us (not for their own purposes)
  • Must comply with applicable privacy laws (GDPR, CCPA)

3.2 Internal Access

Who at OpenAssist can access your data:

  • Support team: To troubleshoot issues, answer questions, resolve billing disputes
  • Engineering team: To debug errors, deploy infrastructure, monitor system health
  • Authorized contractors: Subject to confidentiality agreements

Access controls:

  • All access is logged and monitored
  • No one can access your AI API keys (encrypted, inaccessible to us)
  • We do NOT read your chat messages or prompts unless you explicitly share them for support purposes

3.3 We Do NOT Sell Your Data

OpenAssist does NOT:

  • Sell personal information to third parties
  • Share data with advertisers or data brokers
  • Monetize your information beyond subscription fees
  • Provide data to marketing companies for cross-site tracking

3.4 Legal Disclosures

We may disclose your information if required by law:

  • Court orders, subpoenas, or legal process
  • Law enforcement requests (with valid legal authority)
  • National security demands (if legally compelled)
  • Fraud investigations (cooperation with authorities)

We will:

  • Notify you of legal requests (unless prohibited by law or court order)
  • Challenge overly broad or unjustified requests
  • Only disclose the minimum data required

3.5 Business Transfers

If OpenAssist is acquired, merged, or sells assets:

  • User data may be transferred to the acquiring company
  • You will be notified via email 30 days in advance
  • The acquirer must honor this Privacy Policy (or obtain your consent for changes)
  • You may delete your account before the transfer if you disagree

4. DATA RETENTION & DELETION

4.1 Active Accounts

While your account is active, we retain:

  • All service data (tasks, agents, protocols, schedules, logs) indefinitely
  • Chat history and activity logs
  • Billing records (for tax and accounting)

4.2 Immediate Deletion Upon Cancellation

When you cancel your subscription or destroy an agent:

  • DigitalOcean droplets are destroyed within minutes (all agent data lost permanently)
  • Supabase data (tasks, agents, protocols, logs) is deleted immediately
  • Dashboard access is revoked
  • No recovery or grace period—deletion is instant and irreversible

Before canceling, you should:

  • Export important data manually via the dashboard
  • Download chat logs and task history
  • Backup agent memory files via SSH (you have full root access to your droplet)

4.3 Backup Retention

Encrypted database backups (for disaster recovery) are retained for 90 days, then automatically purged.

Important:

  • Backups are not accessible to you or our team after account deletion
  • Used only for catastrophic system failures (not individual account recovery)
  • Encrypted and stored securely

4.4 Legal & Financial Records

Permanently retained (required by law):

  • Financial records (invoices, payment history): 7 years (tax/accounting compliance)
  • Anonymized audit logs (fraud prevention): No personally identifiable information (PII)

4.5 Marketing Data (Brevo)

If you opt out of marketing emails:

  • Your email remains in Brevo’s database (to honor opt-out preference)
  • Marked as “unsubscribed” (no marketing emails sent)
  • Deleted from Brevo within 90 days of account deletion

5. DATA SECURITY

5.1 Encryption

In Transit (TLS/HTTPS):

  • All connections use TLS 1.3 encryption (HTTPS)
  • Dashboard ↔ Supabase: Encrypted
  • Dashboard ↔ DigitalOcean API: Encrypted
  • Chat ↔ OpenClaw agent: Encrypted via HTTPS
  • API calls to Stripe, Brevo, Google: Encrypted

At Rest (AES-256):

  • Supabase: Database encryption (PostgreSQL with encryption at rest)
  • DigitalOcean: Droplet volumes encrypted (provider-managed)
  • Stripe: Payment data encrypted (PCI-DSS Level 1 compliant)
  • API keys: Stored as encrypted environment variables (AES-256/bcrypt)

5.2 Access Controls

Authentication:

  • OAuth 2.0 via Google (industry-standard security)
  • Supabase Row Level Security (RLS) policies (users can only access their own data)
  • Session tokens with automatic expiration (24-hour max)
  • Password hashing (bcrypt with high cost factor)

Infrastructure security:

  • Vercel: DDoS protection, automatic HTTPS, CDN caching, isolated serverless functions
  • Cloudflare: DNS security, DDoS mitigation, Web Application Firewall (WAF)
  • DigitalOcean: Network firewalls, isolated droplets, SSH key authentication

5.3 Application Security Measures

  • Input validation: Prevent SQL injection, XSS attacks
  • CSRF protection: Tokens on all state-changing requests
  • Rate limiting: Prevent brute-force login attempts and API abuse
  • Dependency updates: Regular security patches for libraries
  • Code reviews: Manual and automated security audits

5.4 Monitoring & Incident Response

Proactive monitoring:

  • Failed login attempt tracking (IP-based rate limiting)
  • Anomaly detection (unusual API usage patterns, mass data exports)
  • Real-time alerts for suspicious activity
  • Regular security audits and penetration testing (as we scale)

Incident response plan:

  • Detection: Automated alerts + manual monitoring
  • Containment: Isolate affected systems, revoke compromised credentials
  • Eradication: Patch vulnerabilities, remove threats
  • Recovery: Restore from secure backups if needed
  • Notification: Email affected users within 72 hours (GDPR requirement)

5.5 Data Breach Notification

If a security breach occurs affecting your data:

We will notify you within 72 hours via email with:

  • What happened: Description of the breach (how it occurred, when discovered)
  • What data was affected: Types of information compromised (email, tasks, etc.)
  • What we’re doing: Steps to remediate the breach and prevent recurrence
  • What you should do: Recommended actions (change passwords, rotate API keys, monitor accounts)

Regulatory notification:

  • EU users: Notification to relevant Data Protection Authority (GDPR)
  • California users: Notification per California Civil Code § 1798.82 (CCPA)
  • Other jurisdictions: As required by applicable laws

No breach has occurred as of this policy’s effective date.


6. YOUR PRIVACY RIGHTS

6.1 Right to Access Your Data

You can access your data at any time:

Self-service (via dashboard):

  • View all tasks, agents, protocols, schedules, activity logs
  • Download chat history (manual export via UI)
  • Access agent memory files via SSH (full root access to your DigitalOcean droplet)

Formal data access request:

  • Email privacy@openassist.io with your registered email address
  • We’ll provide a comprehensive data export (JSON/CSV format) within 30 days

What you’ll receive:

  • Account information (email, display name, subscription status)
  • Service usage data (tasks, agents, protocols, schedules, activity logs)
  • Billing history (invoices, payment dates)
  • Technical data (IP addresses, login timestamps)

Note: We cannot provide your AI API keys (encrypted, inaccessible to us).

6.2 Right to Delete Your Data

You can delete your data at any time:

Self-service deletion (immediate):

  1. Cancel subscription via dashboard settings → Agent destroyed + data deleted instantly
  2. Destroy individual agent instances → Droplet deleted, memory lost permanently

Full account deletion:

  1. Email privacy@openassist.io with subject line “Account Deletion Request”
  2. We’ll verify your identity (security questions or email confirmation)
  3. Account and all data deleted within 7 days

What gets deleted:

  • All Supabase data (tasks, agents, protocols, logs, chat history)
  • DigitalOcean droplets (agents destroyed)
  • Dashboard access revoked
  • Marketing email subscriptions (removed from Brevo)

What remains (legal requirements):

  • Financial records (invoices, payment history) for 7 years (tax compliance)
  • Anonymized audit logs (no PII) for fraud prevention

6.3 Right to Export Your Data (Data Portability)

You can export your data in machine-readable formats:

Self-service export:

  • Dashboard allows downloading task lists, activity logs (JSON/CSV)
  • SSH access to your droplet (full file system access to agent memory)

Formal export request:

  • Email privacy@openassist.io
  • We’ll provide a comprehensive data package within 30 days
  • Formats: JSON, CSV (structured, easy to import elsewhere)

6.4 Right to Correct Your Data

Update inaccurate information:

Self-service:

  • Edit display name, profile picture via account settings
  • Update agent configurations, task details, protocols via dashboard

Email us:

  • If you find errors we cannot fix via UI, email privacy@openassist.io
  • We’ll correct inaccuracies within 15 days

6.5 Right to Opt Out of Marketing

Unsubscribe from promotional emails:

Immediate opt-out:

  • Click “Unsubscribe” link at the bottom of any marketing email
  • Preferences updated in Brevo within 24 hours

Dashboard settings:

  • Toggle “Receive marketing emails” off in account settings (if we add this feature)

Email us:

Note: You cannot opt out of transactional emails (billing, security alerts—required for account management).

6.6 Right to Restrict Processing

Limit how we use your data:

If you believe data is inaccurate or processing is unlawful:

  • Email privacy@openassist.io with your concern
  • We’ll restrict processing (e.g., stop using data for analytics) while investigating
  • You retain access to the Service (unless restriction prevents core functionality)

6.7 Right to Object to Processing

Object to specific data uses:

You can object to:

  • Marketing: Opt out via unsubscribe links or email preferences@openassist.io
  • Analytics: Disable Google Analytics via cookie consent banner

You cannot object to:

  • Service provision: Processing required to operate OpenAssist (authentication, billing, agent management)
  • Legal compliance: Processing required by law (tax records, fraud prevention)

7. GDPR COMPLIANCE (EU/EEA Users)

If you are located in the European Union (EU), European Economic Area (EEA), United Kingdom (UK), or Switzerland, you have additional rights under the General Data Protection Regulation (GDPR).

7.1 Legal Basis for Processing

We process your personal data under the following legal bases:

Data TypeLegal BasisGDPR Article
Account info, subscription, service usageContract (necessary to provide the Service)Art. 6(1)(b)
Payment processingContract (necessary for billing)Art. 6(1)(b)
Marketing emailsConsent (opt-in via signup or explicit consent)Art. 6(1)(a)
Analytics (Google Analytics)Legitimate interest (improve service, with opt-out available)Art. 6(1)(f)
Fraud prevention, securityLegitimate interest (protect users and our business)Art. 6(1)(f)
Legal complianceLegal obligation (tax records, law enforcement requests)Art. 6(1)(c)

7.2 Data Transfers Outside the EU

Your data may be transferred to the United States:

OpenAssist’s infrastructure is primarily US-based:

  • Supabase: Data centers in US (with EU region option if selected)
  • DigitalOcean: You choose droplet region (Amsterdam, Frankfurt available for EU users)
  • Vercel: US-based, with global CDN
  • Stripe: US company, GDPR-compliant data processing

Transfer safeguards:

  • Standard Contractual Clauses (SCCs): EU-approved contracts with US vendors (Supabase, Stripe, Google, Brevo)
  • Adequacy decisions: UK and Switzerland have adequacy decisions allowing data flows
  • EU hosting option: You can deploy agents in EU DigitalOcean regions (Amsterdam, Frankfurt) to keep agent data in the EU

7.3 Data Protection Officer (DPO)

For GDPR inquiries:

7.4 Right to Lodge a Complaint

If you believe we’ve violated GDPR, you may:

  1. Contact us first: privacy@openassist.io (we’ll resolve issues promptly)
  2. File a complaint with your local Data Protection Authority (DPA):

7.5 Consent Withdrawal

You can withdraw consent at any time (for marketing emails, analytics cookies):

  • Effect: We stop processing data for that purpose
  • Does not affect past processing (while consent was valid)
  • Does not affect processing based on other legal bases (contract, legal obligation)

To withdraw consent:

  • Marketing emails: Unsubscribe link or email preferences@openassist.io
  • Analytics cookies: Disable via cookie consent banner or browser settings

8. CCPA COMPLIANCE (California Residents)

If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA).

8.1 Categories of Personal Information We Collect

CategoryExamplesCollected?
IdentifiersName, email, IP address, user ID✅ Yes
Commercial informationSubscription plan, billing history, payment method✅ Yes
Internet activityPage views, clicks, usage logs (via Google Analytics)✅ Yes
GeolocationApproximate location (city/country from IP), droplet region✅ Yes
InferencesUser preferences, behavior patterns (from analytics)✅ Yes
Sensitive personal informationAPI keys (encrypted, inaccessible to us)✅ Yes (but secured)
Biometric informationNone❌ No
Health dataNone❌ No
Financial account detailsNone (Stripe handles payment, we don’t store card numbers)❌ No

8.2 How We Use Personal Information

We use your data to:

  • Provide the Service (agent deployment, dashboard, billing)
  • Improve the Service (analytics, debugging)
  • Communicate with you (emails, notifications)
  • Prevent fraud and enforce Terms

We do NOT sell your personal information. (See CCPA § 1798.120)

8.3 Your California Privacy Rights

Right to Know (CCPA § 1798.100):

  • Request what personal information we’ve collected about you (see Section 6.1)

Right to Delete (CCPA § 1798.105):

  • Request deletion of your personal information (see Section 6.2)
  • Exceptions: Legal compliance, fraud prevention, financial records (7-year retention)

Right to Correct (CCPA § 1798.106):

  • Request correction of inaccurate information (see Section 6.4)

Right to Opt Out of Sale/Sharing (CCPA § 1798.120):

  • We do NOT sell your personal information—opt-out not applicable
  • We do NOT share data for cross-context behavioral advertising

Right to Limit Use of Sensitive Information (CPRA § 1798.121):

  • We only use sensitive information (API keys) for Service provision (not for analytics or marketing)
  • No action needed—already limited to essential purposes

Right to Non-Discrimination (CCPA § 1798.125):

  • We will NOT discriminate against you for exercising your rights
  • No denial of service, different pricing, or degraded experience

8.4 How to Exercise Your California Rights

Submit a request:

  1. Email privacy@openassist.io with subject line “CCPA Request”
  2. Include:
    • Your registered email address
    • Specific right you’re exercising (know, delete, correct)
    • Verification details (we may ask security questions)

Response timeline:

  • Acknowledgment: Within 10 days
  • Fulfillment: Within 45 days (may extend to 90 days if complex, with notice)

Verification process:

  • We’ll verify your identity via email confirmation or security questions
  • For sensitive requests (deletion), we may require additional verification

Authorized agents:

  • You may designate someone to submit requests on your behalf
  • Provide written authorization or power of attorney

8.5 Shine the Light Law (California Civil Code § 1798.83)

California residents may request information about personal information shared with third parties for direct marketing purposes.

OpenAssist does NOT share your data with third parties for their direct marketing.

If you want confirmation, email privacy@openassist.io with “Shine the Light Request” in the subject line.

8.6 Do Not Track (DNT) Signals

We do NOT currently respond to “Do Not Track” (DNT) browser signals.

Why? No industry standard exists for interpreting DNT signals. However:

  • You can disable Google Analytics via our cookie consent banner
  • You can block cookies via browser settings

9. COOKIES & TRACKING TECHNOLOGIES

9.1 What Are Cookies?

Cookies are small text files stored by your browser. We use cookies to:

  • Keep you logged in (authentication)
  • Remember your preferences (active agent selection)
  • Analyze usage patterns (Google Analytics)

9.2 Types of Cookies We Use

Essential Cookies (Required)

Cookie NamePurposeDurationCan Opt Out?
sb-auth-tokenSupabase authentication session24 hours❌ No (required for login)
sb-refresh-tokenKeeps you logged in across sessions30 days❌ No (required for login)

Browser localStorage (not cookies, but similar):

  • openclaw_active_instance: Remembers your last selected agent | Persistent | ✅ Yes (clear browser data)

Analytics Cookies (Optional)

Cookie NamePurposeDurationCan Opt Out?
_gaGoogle Analytics: Distinguishes users2 years✅ Yes (cookie banner)
_ga_*Google Analytics: Stores session state2 years✅ Yes (cookie banner)
_gidGoogle Analytics: Distinguishes users (short-term)24 hours✅ Yes (cookie banner)

What Google Analytics tracks:

  • Page views and navigation (which features you use)
  • Session duration (how long you stay on the dashboard)
  • Device and browser info (to optimize for your platform)

What Google Analytics does NOT track:

  • Your identity (email, name)—data is pseudonymized
  • Chat message content or AI prompts
  • API keys or sensitive credentials

IP anonymization:

  • Google Analytics anonymizes the last octet of your IP address (e.g., 192.168.1.XXX)
  • Full IP address is never stored by Google

Marketing Cookies (Not Currently Used)

We do not currently use marketing/retargeting cookies (e.g., Facebook Pixel, Google Ads remarketing).

If we add them in the future:

  • 30 days’ notice via email
  • Explicit opt-in required (GDPR) or opt-out mechanism (CCPA)
  • Updated Privacy Policy with details

9.3 Cookie Consent Banner

When you first visit OpenAssist:

EU/EEA/UK users (GDPR):

  • Explicit consent required before non-essential cookies (analytics) are set
  • Cookie banner appears: “We use cookies for authentication and analytics. [Accept All] [Essential Only] [Customize]”
  • If you decline analytics, Google Analytics is not loaded

US/Non-EU users:

  • Notice-based approach: Banner informs you of cookie use
  • Analytics cookies load by default (you can opt out via banner or browser settings)
  • Complies with CCPA (you can disable via “Do Not Sell My Personal Information” link)

Your choices:

  • Accept All: All cookies enabled (authentication + analytics)
  • Essential Only: Only required cookies (authentication)—Google Analytics disabled
  • Customize: Choose which categories to enable/disable

Banner behavior:

  • Appears on first visit (or after clearing cookies)
  • Choice stored in localStorage (persists across sessions)
  • Can revisit choices via “Cookie Preferences” link in footer

9.4 Managing Cookies

Browser controls:

  • Chrome: Settings > Privacy > Cookies
  • Firefox: Settings > Privacy > Cookies and Site Data
  • Safari: Preferences > Privacy > Cookies
  • Edge: Settings > Privacy > Cookies

Disable all cookies:

  • Effect: You will be logged out and cannot use OpenAssist (authentication cookies required)

Disable analytics cookies only:

Clear existing cookies:

  • Browser settings > Clear browsing data > Cookies
  • Effect: You’ll be logged out and need to sign in again

9.5 Third-Party Tracking

We do NOT use:

  • Cross-site tracking pixels
  • Advertising networks (Google Ads, Facebook Ads retargeting)
  • Data brokers or affiliate tracking
  • Browser fingerprinting

Third-party cookies from our vendors:

  • Google Analytics: As described in Section 9.2
  • Stripe: May set cookies during payment flow (governed by Stripe’s policy)

Social media embeds:

  • We do not embed Facebook Like buttons, Twitter feeds, or similar tracking widgets

10. CHILDREN’S PRIVACY

OpenAssist is NOT intended for children under 18.

Our Terms of Service require users to be at least 18 years old. We do not knowingly collect personal information from minors.

COPPA Compliance (USA):

  • Not applicable (we target adults, not children under 13)

If we discover a child’s account:

  • Immediate termination of account
  • Deletion of all associated data
  • Notification to parent/guardian (if contact information is available)

Parents/Guardians:
If you believe your child has created an account, email privacy@openassist.io immediately. We’ll delete the account within 24 hours.


11. INTERNATIONAL DATA TRANSFERS

OpenAssist operates primarily in the United States. If you access the Service from outside the US, your data may be transferred to and processed in the US.

11.1 EU/EEA/UK/Switzerland → US Transfers

Data protection safeguards:

  • Standard Contractual Clauses (SCCs): EU-approved contracts with US vendors (Supabase, Google, Stripe, Brevo)
  • EU Data Hosting Option: Deploy agents in DigitalOcean EU regions (Amsterdam, Frankfurt) to keep agent data within the EU
  • GDPR Compliance: All vendors are GDPR-compliant (data processing agreements in place)

UK transfers:

  • UK government has issued an “adequacy decision” for US data transfers under the UK-US Data Bridge
  • No additional safeguards required for UK → US transfers

Swiss transfers:

  • Switzerland has an adequacy decision with the US (Privacy Shield 2.0 framework)

11.2 Other Jurisdictions

Brazil (LGPD):

  • Brazilian users’ data may be transferred to the US (we’re US-based)
  • LGPD allows international transfers if adequate safeguards exist (contracts with vendors, encryption)

Other countries:

  • If your country restricts data transfers, you acknowledge that using OpenAssist involves transferring data to the US
  • You consent to this transfer by using the Service

12. DATA BREACH NOTIFICATION

12.1 What Constitutes a Breach?

A data breach occurs when unauthorized parties gain access to:

  • Personal information (email, name, IP addresses)
  • Service data (tasks, agent configurations, chat logs)
  • Credentials (passwords, API keys, tokens)

Not considered breaches:

  • Authorized access by you or our support team (with your consent)
  • Anonymized analytics data leaks (no PII)
  • Public information (e.g., your agent’s public GitHub repo, if you choose to share it)

12.2 Notification Timeline

Within 72 hours of discovery, we will:

Email affected users with:

  • What happened: Description of the breach (attack vector, date/time discovered)
  • What data was compromised: Specific types of information accessed (email, tasks, etc.)
  • What we’re doing: Immediate containment steps, security patches, forensic investigation
  • What you should do: Recommended actions (change passwords, rotate API keys, monitor accounts)

Notify regulators (if required):

  • EU/EEA: Report to lead Data Protection Authority within 72 hours (GDPR Art. 33)
  • California: Report to Attorney General if >500 California residents affected (CCPA)
  • Other jurisdictions: As required by local laws

12.3 Our Response Process

Immediate (0-24 hours):

  1. Detect & contain: Isolate affected systems, revoke compromised credentials
  2. Assess impact: Determine what data was accessed, how many users affected
  3. Preserve evidence: Log forensic data for investigation

Short-term (24-72 hours):
4. Notify users: Send breach notification emails
5. Notify regulators: File required reports (GDPR, CCPA)
6. Patch vulnerabilities: Fix security flaws, update systems

Long-term (72+ hours):
7. Investigation: Root cause analysis, third-party security audit (if needed)
8. Post-mortem: Document lessons learned, improve security measures
9. Ongoing monitoring: Enhanced detection for similar attacks

12.4 Your Responsibilities After a Breach

If notified of a breach, you should:

  • Change passwords: Update your OpenAssist password and Google account password
  • Rotate API keys: Generate new Anthropic/OpenAI keys, revoke old ones
  • Monitor accounts: Watch for suspicious activity on linked services (Stripe, email)
  • Enable 2FA: If we add two-factor authentication, enable it immediately

We will NOT:

  • Ask you to “verify” your account via email links (phishing risk)
  • Request your password or API keys (we never need these)

13. CONTACT & DATA PROTECTION

13.1 Privacy Contact

For all privacy-related inquiries:

  • Email: privacy@openassist.io
  • Response time: 3 business days for general inquiries, 30 days for formal data requests
  • Subject line examples: “GDPR Data Access Request,” “CCPA Deletion Request,” “Cookie Opt-Out”

13.2 Data Subject Requests

To exercise your rights (access, delete, export, correct):

Step 1: Email us

Step 2: Verification

  • We’ll verify your identity (email confirmation or security questions)
  • For sensitive requests (deletion), additional verification may be required

Step 3: Fulfillment

  • GDPR: 30 days (may extend to 90 days if complex, with notice)
  • CCPA: 45 days (may extend to 90 days if complex, with notice)
  • Other users: 30 days (best-effort basis)

No fee for first request (excessive/repetitive requests may incur reasonable administrative fees).

13.3 General Support

For non-privacy issues:

13.4 Legal Contact

For legal matters:

  • Email: legal@openassist.io
  • Topics: Subpoenas, court orders, law enforcement requests, arbitration notices

13.5 Physical Address (Mailing)

IANternet Media
[Your NJ Business Address]
[City, State, ZIP Code]


14. UPDATES TO THIS PRIVACY POLICY

14.1 When We Update This Policy

We may update this Privacy Policy when:

  • New features are added that affect data collection (e.g., new integrations)
  • Legal requirements change (new privacy laws, regulatory guidance)
  • Third-party policies change (vendor updates to Supabase, Google Analytics, etc.)
  • User feedback identifies ambiguities or missing information

Annual review: We review this policy at least once per year (even if no changes).

14.2 How We Notify You

Material changes (affecting your rights or data usage):

  • Email notification 30 days in advance to all registered users
  • Dashboard banner highlighting key changes (with link to full policy)
  • Blog post explaining updates (if significant)
  • Updated “Last Modified” date at the top of this page

Minor changes (typo fixes, clarifications, formatting):

  • Updated “Last Modified” date only (no proactive notification)
  • Changes take effect immediately upon posting

14.3 Acceptance of Changes

Continued use of OpenAssist after the effective date = acceptance of the updated policy.

If you disagree with changes:

  1. Email privacy@openassist.io to express concerns (we may address them)
  2. Cancel your subscription before the effective date to avoid being bound by new terms
  3. Request account deletion if you no longer wish to use the Service

Changes do not apply retroactively—previous versions govern past data processing.

14.4 Policy Version History

Current version: 1.0 (Effective February 10, 2026)

Previous versions: None (initial version)


15. ADDITIONAL PRIVACY INFORMATION

15.1 Automated Decision-Making

We do NOT use automated decision-making or profiling that significantly affects you:

  • No AI-based credit scoring or eligibility decisions
  • No automated content moderation (you control your agent)
  • No behavioral predictions influencing service access

Google Analytics inferences (e.g., “this user prefers Protocol X”) are used only for aggregate analytics, not individual decisions.

15.2 Sensitive Personal Information

What we consider sensitive:

  • API keys (Anthropic, OpenAI, DigitalOcean tokens)
  • Payment information (stored by Stripe, not us)
  • Chat logs (may contain personal thoughts, business data)

How we protect sensitive data:

  • Encryption at rest and in transit (AES-256, TLS 1.3)
  • Access controls: Only you can access your data (via dashboard or SSH)
  • No training: We never use your data to train AI models
  • Immediate deletion: Upon account cancellation, sensitive data is destroyed

15.3 Marketing & Communications

What you’ll receive:

Transactional (mandatory):

  • Welcome email (account creation)
  • Billing notifications (payment success/failure, renewal reminders)
  • Security alerts (suspicious login, password change)
  • Service updates (critical bug fixes, planned maintenance)

Marketing (optional, opt-in):

  • Product updates and new features
  • Tips and tutorials for using OpenAssist
  • Blog posts and industry insights
  • Promotional offers (discounts, referral programs)

Frequency:

  • Transactional: As needed (typically <5 per month)
  • Marketing: ~2-4 per month (you control frequency via preferences)

Opt-out:

  • Click “Unsubscribe” in any marketing email (instant)
  • Email preferences@openassist.io
  • Adjust settings in dashboard (if we add this feature)

15.4 Third-Party Links

Our dashboard may contain links to third-party sites:

  • OpenClaw documentation (openclaw.ai)
  • AI provider dashboards (Anthropic, OpenAI)
  • DigitalOcean console
  • Stripe billing portal

We are NOT responsible for:

  • Privacy practices of third-party sites
  • Content or security of external links
  • Data collected by linked services

Before clicking external links, review their privacy policies.

15.5 Social Media

We do NOT:

  • Embed social media widgets (Facebook Like, Twitter follow buttons)
  • Share your data with social media platforms (unless you explicitly connect accounts)

If we add social features in the future:

  • Explicit opt-in required (GDPR)
  • Updated Privacy Policy with full disclosure

16. SUMMARY OF KEY POINTS

What we collect: Email, payment info (via Stripe), service data (tasks, agents, chat logs), technical data (IP, browser), analytics (Google Analytics)

How we use it: Provide service, improve features, send emails (transactional + marketing), prevent fraud

Who we share with: Supabase (database), DigitalOcean (hosting), Vercel (dashboard), Stripe (payments), Google Analytics, Brevo (emails)—no data selling

Your rights: Access, delete, export, correct, opt out of marketing, limit analytics (via cookie banner)

Data deletion: Immediate upon account cancellation (no recovery)—backups retained 90 days (encrypted, inaccessible)

Security: TLS encryption, AES-256 at rest, access controls, breach notification within 72 hours

Compliance: GDPR (EU), CCPA (California), LGPD (Brazil)—international data transfers with safeguards

Cookies: Essential (auth) + optional analytics (Google)—cookie banner for GDPR compliance

Contact: privacy@openassist.io for all privacy requests (30-day response)


17. CONSENT & ACCEPTANCE

By using OpenAssist, you:

  • Acknowledge you have read and understood this Privacy Policy
  • Consent to the data practices described herein
  • Agree to the collection, use, and sharing of your information as outlined
  • Accept international data transfers (if outside the US)

If you do not agree, please do not create an account or use the Service.

Last Updated: February 10, 2026
Effective Date: February 10, 2026
Version: 1.0


Thank you for trusting OpenAssist with your data. We take your privacy seriously.

For questions or concerns, contact us at privacy@openassist.io.